Effective date: August 2026
Saga ("Saga", "we", "us") is an endurance-training app operated by an individual developer (Ryan Sharp). This policy explains what we collect, why, and your choices. Questions: rtsharp90@gmail.com.
What we collect
Account
When you sign in with Apple, we receive an identifier and, if you choose to share it, your name and email (which may be Apple's private relay address). You choose a unique username shown publicly on plans you publish.
Training data
Plans you follow or create, your start dates and enrollments, sessions you mark complete, and reviews you write.
Workout / activity data
With your permission, completed activity data — activity type, start time, duration, distance, average heart rate, and calories — from:
- Apple Health (HealthKit), read on your device; and
- Garmin and COROS, if you connect those accounts.
We request read-only activity data — not steps, sleep, or continuous health monitoring. If you connect Garmin and enable it, we also send your planned workouts to your Garmin account or device (Garmin Training API).
How we use it
Only to provide the service: to show your training plan, match your completed workouts to it, display your adherence and progress, and — for plans you publish — list them in the marketplace attributed to your username. We do not sell your data or use it for advertising.
What's visible to others
- Plans you publish are public in the marketplace, attributed to your username.
- Reviews you post are visible on the plan you reviewed.
- Your workouts, progress, and enrollments are private to you — never shown to other users.
Who we share it with
We don't sell your data. We use these processors to run the app:
- Apple — Sign in with Apple, and HealthKit on your device.
- Supabase — our backend hosting and database.
- Garmin / COROS — only if you connect them, to import your activities (and, for Garmin, to send planned workouts).
Connecting a wearable is done via OAuth; the access tokens are stored on our server and never exposed in the app.
Storage, security, and retention
Your data is stored in our Supabase (Postgres) backend with per-user access controls, so you can only access your own data. We keep it while your account is active. You can disconnect a wearable at any time, and request deletion of your account and data by contacting us.
Your choices and rights
- Disconnect Apple Health, Garmin, or COROS at any time (in the app or the provider's settings) — new activities stop importing.
- Access or delete your data by emailing rtsharp90@gmail.com.
- Depending on where you live, you may have rights to access, correct, or delete your personal data; contact us to exercise them.
Children
Saga isn't directed to children under 13 (or the minimum age in your country), and we don't knowingly collect their data.
Changes
We'll update this policy as the app evolves and revise the effective date above.
Contact
Ryan Sharp — rtsharp90@gmail.com